vendor:
DelphiTurk FTP
by:
Kozan
5.5
CVSS
MEDIUM
Local Password Disclosure
200
CWE
Product Name: DelphiTurk FTP
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:delphiturk:ftp:1.0
Platforms Tested: Windows
2005
DelphiTurk FTP v1.0 Local Exploit
This exploit allows an attacker to retrieve local user passwords from DelphiTurk FTP v1.0. The exploit uses a vulnerability in the application to read the password data from the 'profile.dat' file.
Mitigation:
The vendor should release a patch to fix the vulnerability. In the meantime, users should consider using a different FTP client.